Junglewise Threat Intelligence

CVE-2026-8124: GPAC resource consumption in sidx_box_read

CVE-2026-8124 · Severity: low · CVSS 3.3 · Published 2026-05-08

Technologies: Gpac. Vendors: Gpac.

Executive brief

GPAC is an open-source multimedia framework used for video streaming and packaging. A vulnerability in its media file processing component allows a local attacker to cause the application to consume excessive memory. This can lead to a denial-of-service condition, potentially crashing the software or impacting the performance of the host system.

Technical details

A resource consumption vulnerability (CWE-400/CWE-770) exists in GPAC versions up to 26.02.0 within the sidx_box_read function in src/isomedia/box_code_base.c. The vulnerability is caused by unchecked memory allocation when reading Segment Index (sidx) boxes in media files. A local attacker can exploit this by providing a specially crafted file that triggers excessive memory allocation, leading to a denial-of-service (DoS) through memory exhaustion. The issue has been addressed in commit 442e2299530138d8f874fd885c565ba98a6318ba.

Affected products

  • GPAC GPAC up to 26.02.0

Timeline

  • 2026-05-08: advisory: Initial disclosure date
  • 2026-05-08: patched: Patch identified as commit 442e2299530138d8f874fd885c565ba98a6318ba

References

Related threats